vulnerability Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second Researchers have demonstrated a significant vulnerability in Cloudflare Workers, allowing a remote Spectre attack to leak JWTs from co-located Workers at a rate up to 12 bits per second. Despite previous mitigations like DyPrIs, the underlying detection approach remains insufficient, highlighting a fundamental limitati… The Hacker News · Aug 19, 2026 High spectredyprisjwt
vulnerability Attackers Exploit SharePoint Authentication Bypass After Public PoC Release Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) due to a bypass in the authentication feature. Following the release of a proof-of-concept by Rapid7, attackers are lev… The Hacker News · Aug 13, 2026 Critical CVE-2026-55040HOJANEjwtauthenticationsharepoint
vulnerability Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE Researchers at Rapid7 discovered a chain of vulnerabilities in Microsoft SharePoint, allowing unauthenticated attackers to impersonate users, including administrators, through a complex AI-assisted process. The initial b… The Hacker News · Aug 11, 2026 High CVE-2026-55040CVE-2026-63520jwtsharepointrce
vulnerability Siemens Opcenter X Siemens Opcenter X versions prior to V2604 contain a critical authentication bypass vulnerability, allowing an unauthenticated attacker to gain full unauthorized access to the application. Siemens has released a new vers… CISA Advisories · Jul 21, 2026 Critical CVE-2026-56451DEauthenticationjwtcwe-347
vulnerability n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer A vulnerability in n8n’s Enterprise token exchange feature allows attackers to log in as users from another issuer if the platform trusts more than one external token issuer. The flaw stems from a mismatch between the is… The Hacker News · Jul 16, 2026 High CVE-2026-59208CVE-2026-54305jwttokenidentity-binding
vulnerability RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata Two vulnerabilities in RabbitMQ could allow attackers to steal OAuth secrets, expose tenant data, and potentially take over entire messaging infrastructure. The flaws have been patched, but organizations need to take imm… The Hacker News · Jul 14, 2026 High CVE-2026-57219CVE-2026-57221rabbitmqoauthvulnerability